Re: Security question on DNS zone transfers

From: Dave Nickason [SBS MVP] (gwdibble_at_NOSPAM.frontiernet.net)
Date: 07/08/04


Date: Thu, 8 Jul 2004 12:52:21 -0400

Assuming you're referring to the Zone Transfer tab in the properties of the
Forward Lookup Zone, you want to allow zone transfers only to servers listed
on the Name Servers tab. On Name Servers, you'd have only your SBS and any
other DNS server in your local domain (generally none - SBS would be the
only one listed).

FWIW, your DNS settings as configured in the SBS install process and by the
ICW should be correct. No manual intervention should be necessary.

"Mark Holoweiko" <mh@stonypoint-pr.com> wrote in message
news:4vOdnRD0nceMw3DdRVn-hA@comcast.com...
> In DNS settings for Forwarders, should zone transfers be allowed "to any
> server" or be limted to named servers only?
>
> If the latter, which other servers should be listed?
>
> Situation: SBS2000, two NICs, and using a dynamic DNS service (DNS2GO) to
> host Exchange e-mail and (gulp) web site.
>
> Any assistance much appreciated.
>
>
>



Relevant Pages

  • Re: Primary/Secondary DNS ??
    ... On the zone transfer tab should I only be adding each other's IP ... Allow zone transfers to those on the DNS tab ... One the Secondary there is no reason to add ANY servers ... secondaries. ...
    (microsoft.public.win2000.dns)
  • RE: DNS ACL ?
    ... and there should be no zone transfers coming in ... from the internet to these servers. ... Subject: DNS ACL? ... > Not all DNS clients automatically try to negotiate bigger UDP ...
    (Pen-Test)
  • Re: Zone Transfer and Trust
    ... > local AD Integrated DNS servers at both locations? ... Herb Martin ... >>> Do we need to do Zone transfers from one DNS to another DNS to ...
    (microsoft.public.windows.server.dns)
  • RE: Pubstro rash
    ... As far as I'm concerned DNS just uses 53/TCP to do zone transfers. ... Tipically zone transfers would only be used by secondary servers to update ... Cipher - Segurança da Informação ...
    (Incidents)
  • Security question on DNS zone transfers
    ... In DNS settings for Forwarders, should zone transfers be allowed "to any ... server" or be limted to named servers only? ... which other servers should be listed? ...
    (microsoft.public.backoffice.smallbiz2000)

Quantcast